Investigate and solves security breaches and other cyber security incidents and provide incident response.
Malware analysis, log analysis, RSA , ArcSight SIEM log analysis utilizing Enterprise Products
Preparing roaster and providing assurance of availability of analyst 24*7 without any fail.
Experience in integrating event sources Like; windows, Linux, File etc.
Experience in creating SOC Reports on daily/weekly/Monthly basis.
Analyzing security logs in case of unauthorized access on different security devices.
Performing log analysis & threat analysis.
Creating correlation rule/use cases based on customer requirements
Review security related events, assessing risk and validity, as well as reporting.
Actively investigate the latest in security vulnerabilities, advisories, incidents, and penetration techniques and notify client when appropriate.
Understanding of attack activities, such as scans, man in the middle, sniffing, etc. and possible abnormal activities, such as worms, Trojans, viruses, etc
Experience in intelligence enrichment (Cisco Talons, Whois, Abuseipdb, IBM X Force & virus Total).
Knowledge of security incident response.
Experience in Developing and testing of Content (correlation rules, Reports and Dashboards).
Arc sight SIEM: -
Integration with SIEM, rules, reports and dashboard creation.
Analysis and investigation of information security events (IDS / DLP / SIEM / etc.) in a 24X7 SOC environment to immediately detect, verify, and respond swiftly to cyber